4 ms·
OpenSSH has the best track record, but even it had a zero-day RCE (regreSSHion) in 2024. There are bound to be many more discovered as LLMs capable of doing so
by pak 2mo ago
OpenSSH has the best track record, but even it had a zero-day RCE (regreSSHion) in 2024.
There are bound to be many more discovered as LLMs capable of doing so proliferate among those who don't report such things responsibly.
Keeping port 22 open puts you first in line for such exploits, while keeping it behind another layer (whether it's WireGuard or firewall tricks) would buy time, if not keep attackers away entirely. That seems useful, no?
- ozim 2mo agoKeeping port 22 open puts you first in line for such exploits SSH RCE is a super expensive exploit - no one is firing that one while it still is a 0 day without having really important reason or juicy target.